Betheme

Betheme has 24 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; 23 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 6 high. 2022 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 11 of the records (46%). Other recurring categories include Missing Authorization, Deserialization Of Untrusted Data.

23 of the records (96%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.

11 independent researchers contributed these findings, most of them (7) reported by Dave Jong.

01234567891017.11.2022Today17.11.20228.8Betheme <= 26.5.1.4 - Authenticated (Subscriber+) PHP Object Injection CVSS 8.8 · 17.11.202218.11.20228.8Betheme <= 26.5.1.4 - Authenticated (Subscriber+) PHP Object Injection CVSS 8.8 · 18.11.202221.11.20226.4Betheme <= 26.6.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization Checks to Private Page/Post Data Disclosure CVSS 4.3 · 21.11.20228.8Betheme <= 26.6.2 - Missing Authorization Check on Core Functionality CVSS 8.8 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization to Post Status Change CVSS 4.3 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization to Post Title Change CVSS 4.3 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization to Theme Settings Update CVSS 4.3 · 21.11.202213.04.20236.1Betheme <= 26.7.5 - Reflected Cross-Site Scripting CVSS 6.1 · 13.04.202310.08.20236.5Betheme <= 27.1.1 - Missing Authorization via '_tool_history_delete' CVSS 6.5 · 10.08.202314.11.20236.3Betheme <= 27.1.1 - Missing Authorization CVSS 6.3 · 14.11.202329.08.20248.8Betheme <= 27.5.6 - Authenticated (Contributor+) PHP Object Injection CVSS 8.8 · 29.08.20246.4Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 29.08.202412.09.20246.4Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File CVSS 6.4 · 12.09.202420.01.20256.4Betheme <= 27.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS CVSS 6.4 · 20.01.202515.04.20256.4Betheme <= 28.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 15.04.202502.07.20256.4Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library CVSS 6.4 · 02.07.202505.08.20256.4Betheme <= 28.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 05.08.202506.10.20256.4Betheme <= 28.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 06.10.202508.10.20256.4Betheme <= 28.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_title' CVSS 6.4 · 08.10.202504.05.20266.5Betheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload' CVSS 6.5 · 04.05.20268.8Betheme <= 28.4 - Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload CVSS 8.8 · 04.05.202628.07.20268.8Betheme <= 28.5.7 - Authenticated (Contributor+) Remote Code Execution CVSS 8.8 · 28.07.202625.08.20266.4Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode CVSS 6.4 · 25.08.2026

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage96%
Open

1

Fixed

23

Get automatic notifications for all Betheme vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2024-3998

Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Read the full analysis

Vulnerability Records

24 records
2026-08-25 00:00CVE-2026-6178
6.4
Medium
João Pedro Soares de AlcântaraYes
2026-07-28 00:00CVE-2026-65548
8.8
High
darooYes
2026-05-04 22:35CVE-2026-6261
8.8
High
WebbernautYes
2026-05-04 21:38CVE-2026-6262
6.5
Medium
WebbernautYes
2025-10-08 00:00CVE-2025-9371
6.4
Medium
Zbigniew PiotrakYes
2025-10-06 00:00CVE-2025-63075
6.4
Medium
João Pedro Soares de AlcântaraYes
2025-08-05 15:36CVE-2025-7399
6.4
Medium
stealthcopterYes
2025-07-02 00:00CVE-2024-5647
6.4
Medium
WebbernautYes
2025-04-15 19:05CVE-2025-3077
6.4
Medium
WebbernautYes
2025-01-20 21:55CVE-2025-0450
6.4
Medium
stealthcopterYes
Showing 1–10 of 24 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C